CVE-2026-27100
Java vulnerability analysis and mitigation

Overview

CVE-2026-27100 is a build information disclosure vulnerability in Jenkins core affecting the Run Parameter handling mechanism. Jenkins 2.550 and earlier (weekly) and LTS 2.541.1 and earlier accept Run Parameter values that reference builds the submitting user does not have access to, enabling unauthorized enumeration of job and build metadata. It was disclosed on February 18, 2026, as part of a Jenkins security advisory and was reported through the Jenkins Bug Bounty Program sponsored by the European Commission. The vulnerability carries a CVSS v3.1 base score of 4.3 (Medium) (Jenkins Advisory, Red Hat Bugzilla).

Technical details

The root cause is classified under CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) and CWE-551 (Incorrect Behavior Order: Authorization Before Parsing and Canonicalization), meaning Jenkins processes and accepts Run Parameter values before properly validating whether the requesting user has permission to access the referenced build. An authenticated attacker with Item/Build and Item/Configure permissions can craft a build submission that references builds in jobs outside their authorized scope, and Jenkins will respond with information confirming or denying the existence of those jobs/builds, as well as their display names if they exist. The attack vector is network-based, requires low privileges, and no user interaction (Jenkins Advisory).

Impact

Successful exploitation allows an attacker to perform reconnaissance against the Jenkins infrastructure beyond their assigned permissions — specifically, they can enumerate the existence of restricted jobs, confirm or deny the existence of specific builds, and retrieve display names of builds they are not authorized to view. While there is no direct code execution, integrity, or availability impact, the information gained can facilitate further targeted attacks or expose sensitive CI/CD pipeline structure details (Jenkins Advisory, Red Hat Bugzilla).

Exploitation steps

  1. Reconnaissance: Identify a Jenkins instance running version 2.550 or earlier (weekly) or LTS 2.541.1 or earlier. Confirm the attacker has an account with Item/Build and Item/Configure permissions on at least one project.
  2. Identify target jobs/builds: Determine job names or build IDs that the attacker suspects exist but does not have read access to (e.g., through naming conventions, partial information leakage, or social engineering).
  3. Craft a malicious build submission: When triggering a parameterized build that accepts a Run Parameter, supply a value referencing a build in a restricted job (e.g., specifying a job name and build number the attacker should not have access to).
  4. Observe the response: Jenkins will process the Run Parameter value and, depending on whether the referenced build exists and is accessible, return information confirming the job's existence, the build's existence, or its display name — rather than rejecting the request outright.
  5. Enumerate infrastructure: Repeat the process with different job names and build numbers to map out the Jenkins CI/CD infrastructure, identifying restricted pipelines and build history (Jenkins Advisory).

Indicators of compromise

  • Logs: Jenkins access logs showing repeated parameterized build submissions from a single user referencing diverse job names or build IDs outside their normal project scope; unusual patterns of build trigger requests with Run Parameter values pointing to jobs the user does not own.
  • Behavioral: A low-privileged user account submitting builds with Run Parameters referencing a wide variety of job/build combinations in a short time window, consistent with automated enumeration.
  • Audit: Jenkins audit trail entries showing Item/Build actions by users against jobs they do not have Item/Read permission on.

Mitigation and workarounds

Jenkins has released fixed versions that reject Run Parameter values referencing builds the submitting user cannot access: update to Jenkins weekly 2.551 or Jenkins LTS 2.541.2 (Jenkins Advisory). As an interim measure, restrict Item/Build and Item/Configure permissions to only trusted users, and apply the principle of least privilege across all Jenkins roles. Monitor Jenkins logs for anomalous Run Parameter usage patterns referencing out-of-scope builds. Red Hat has also tracked this issue for affected products (Red Hat Bugzilla).

Community reactions

The vulnerability was reported through the Jenkins Bug Bounty Program sponsored by the European Commission, with credit given to Suman Roy for the discovery (Jenkins Advisory). Several security news outlets covered the advisory, though most coverage conflated it with the higher-severity XSS vulnerability (CVE-2026-27099) disclosed in the same advisory. Community reaction has been relatively muted given the medium severity and the requirement for pre-existing authenticated access.

Additional resources


SourceThis report was generated using AI

Related Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-p279-2cqp-84jgCRITICAL9.6
  • Java logoJava
  • org.openidentityplatform.opendj:opendj-server-legacy
NoYesJul 24, 2026
GHSA-fp43-vj7g-pg92HIGH7.5
  • Java logoJava
  • org.omnifaces:omnifaces
NoYesJul 24, 2026
GHSA-7ppr-r889-mcf2HIGH7.5
  • Java logoJava
  • org.http4s:http4s-blaze-server_2.12
NoYesJul 24, 2026
GHSA-mhvj-jhpq-885vHIGH7.4
  • Java logoJava
  • org.http4s:http4s-blaze-server_2.13
NoYesJul 24, 2026
GHSA-46q4-43ph-c6frHIGH7.4
  • Java logoJava
  • org.http4s:blaze-http_2.12
NoYesJul 24, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management